CVE-2026-94114

Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Credits

The Apache Software Foundation
Claude Security

References